
Vendor risk: assess suppliers without freezing procurement
Questionnaires, SOC 2 evidence, and contract clauses for SaaS and MSP vendors.
Every Puerto Rico SMB depends on dozens of vendors — local MSP, QuickBooks cloud, payroll SaaS, marketing agency with M365 admin access. NIST SP 800-161 guides supply chain risk; enterprise clients ask for TPRM program before signing. Vendor risk assessment must not freeze procurement — tier vendors by criticality and apply proportional rigor.
Tier 1 (prod/PHI/admin access): SIG lite or CAIQ questionnaire, SOC 2 Type II or ISO 27001 evidence, subprocessor review, 72h breach notification clauses, right to audit. Tier 3 (marketing tools without PII): terms review and security page sanity check. Krebs on Security documents breaches starting at small vendor with forgotten access — inventory is step zero.
Contracts: DPA for GDPR/CCPA where applicable, negotiated liability cap, data residency disclosure. Carolina MSP with admin in their tenant must document client segregation. Bruce Schneier recommends least privilege extended to vendors — temporary, logged, quarterly reviewed access.
Automate where possible: minimum viable centralized spreadsheet; Vanta/Drata for scale. Offboarding checklist when canceling vendor — revoke OAuth, change shared passwords, remove Azure AD guest accounts. Shadow IT SaaS discovered in audit is unmanaged vendor risk.
Puerto Rico companies serving mainland clients must align TPRM to client expectations — questionnaire answered honestly with remediation plan beats lying checkbox. Vendor risk is marathon; start with top 5 critical vendors this quarter.

Operations and execution — connecting strategy with what the team ships every week.


